NetScreen
[Top] [All Lists]

[nn] Site-to-site VPN and WMI query failures

To: nn@qorbit.net
Subject: [nn] Site-to-site VPN and WMI query failures
From: Netfortius <netfortius@gmail.com>
Date: Fri, 16 Mar 2007 08:15:32 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: ns-list2@consult.net
Delivered-to: nn@qorbit.net
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:from:reply-to:to:subject:date:user-agent:mime-version:content-type:message-id; b=jWWJGn0ktEo0WlbQzLZnt+81rdGlGErHXQsh5RFvdM27dF18rQTmyus3BDFy2btWi4nXgcARED2E04DnIbe5ncBQT7dZ7L9SynsNzFGY030jZQTMxT08wb6eH5VnK/wqnzI8wiGPzRaa+kUHo+CtxhkosEnjJKRG1y9sqbu8ZFQ=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:reply-to:to:subject:date:user-agent:mime-version:content-type:message-id; b=gQRTkZ3LVmtQPuw6nXOuYy7breYpW1PPs5cOoMJOyyW9FQ+n0Twfuec8KJh0GTAkKOXKsLGRyQAIZSE0EabciiSCoiH4fdge/LDNI8BFJ+kxbAF+6liWFhjosOb02tsQpPBCnMpWhCxjaOSMra4/KzHsDbpfL4nx97KvhiWrymk=
List-archive: <http://www.qorbit.net/nn>
List-help: <mailto:nn-request@qorbit.net?subject=help>
List-id: "Netscreen mailing list for netscreen admins." <nn.qorbit.net>
List-post: <mailto:nn@qorbit.net>
List-subscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=subscribe>
List-unsubscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=unsubscribe>
Reply-to: netfortius@gmail.com
Sender: nn-bounces@qorbit.net
User-agent: KMail/1.9.5
I have a configuration with two sites (in fact many pairs like this, but the 
issue is the same for all pairs) with 5GTs, running all 5.3.0r4.0, connected 
via site-to-site VPN. There are no restrictions of traffic between the LANs 
behind the internal interface of each firewall, and no content rules (took 
them all out). On each LAN there is a Win2K3 DC, and all of those DCs 
communicate and sync just fine (i.e. normal Active Directory traffic works 
perfectly)

When trying to use WMI mmc - i.e. query for WMI properties from one DC to 
another (which consists of some sort of RPC mapper process, first, followed 
by a DCE end points comm attempts, from a source dynamically assigned TCP 
port (the querier) to the destination (the queried system) - always on 
TCP135) this alwasy fails.

What I can see from a trace being taken on the two DCs is that a specific 
segment sent by the querying machine never makes it through the tunnel to the 
other DC (getting dropped by the firewall). Does anybody see anything odd in 
such (failed/being dropped packet here attached - hoe this mailing list 
accepts attachments), that would lead to the above described failure?

NOTE!! TCP checksum incorrect, as reported in the capture, is a tshark 
interpretation. Same "error" showing up in other traces does not keep other 
segments crossing the tunnel, and same "error" does not keep other DCs, on a 
LAN, to work just fine for the WMI queries. It is just the site-to-site 
VPN-oposed-DCs that fail.

TIA,
Stefan

Attachment: failed-packet.txt
Description: Text document

_______________________________________________
nn mailing list
nn@qorbit.net
http://qorbit.net/mailman/listinfo/nn
<Prev in Thread] Current Thread [Next in Thread>
  • [nn] Site-to-site VPN and WMI query failures, Netfortius <=